Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-37770

Publication date:
18/08/2022
libjpeg commit 281daa9 was discovered to contain a segmentation fault via LineMerger::GetNextLowpassLine at linemerger.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2023

CVE-2022-2568

Publication date:
18/08/2022
A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
12/02/2023

CVE-2022-26373

Publication date:
18/08/2022
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2025

CVE-2022-37047

Publication date:
18/08/2022
The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this is different from CVE-2022-27940.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-37048

Publication date:
18/08/2022
The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: this is different from CVE-2022-27941.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-37049

Publication date:
18/08/2022
The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is different from CVE-2022-27942.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-28709

Publication date:
18/08/2022
Improper access control in the firmware for some Intel(R) E810 Ethernet Controllers before version 1.6.1.9 may allow a privileged user to potentially enable denial of service via local access.
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2025

CVE-2022-37768

Publication date:
18/08/2022
libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer.
Severity CVSS v4.0: Pending analysis
Last modification:
20/08/2022

CVE-2022-36727

Publication date:
18/08/2022
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /staff/delete.php.
Severity CVSS v4.0: Pending analysis
Last modification:
22/08/2022

CVE-2022-36728

Publication date:
18/08/2022
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /staff/delstu.php.
Severity CVSS v4.0: Pending analysis
Last modification:
22/08/2022

CVE-2022-36729

Publication date:
18/08/2022
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /librarian/del.php.
Severity CVSS v4.0: Pending analysis
Last modification:
22/08/2022

CVE-2022-26844

Publication date:
18/08/2022
Insufficiently protected credentials in the installation binaries for Intel(R) SEAPI in all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2025